#Sednit
#ESETresearch has analyzed the resurgence of Sednit – one of the most long‑running Russia‑aligned APT groups – now using a modern toolkit built around paired implants, BeardShell and Covenant, each using a different cloud provider for resilience. www.welivesecurity.com/en/eset-rese... 1/5
Sednit reloaded: Back in the trenches
ESET researchers document how the Sednit APT group has reemerged with a modern toolkit centered on two paired implants – BeardShell and Covenant.
www.welivesecurity.com
March 10, 2026 at 2:28 PM
2/2

Information:
APT28 : groupe de cyberespionnage lié à la Russie

APT (Advanced Persistent Threat | Menace Persistante Avancée)

Ce MOA (Mode Opératoire d’Attaque) est également documenté sous les noms de UAC-0028, Fancy Bear, FrozenLake, Sednit, Sofacy ou encore Pawn Storm.
April 29, 2025 at 4:02 PM
#ESETresearch publishes its investigation of Operation RoundPress, which uses XSS vulnerabilities to target high-value webmail servers. We attribute the operation to Sednit with medium confidence. www.welivesecurity.com/en/eset-rese... 1/5
Operation RoundPress targeting high-value webmail servers
ESET researchers uncover a Russia-aligned espionage operation that they named RoundPress and that targets webmail servers via XSS vulnerabilities.
www.welivesecurity.com
May 15, 2025 at 7:36 AM
⚠️ Critical #XSS flaw actively exploited in Zimbra Collaboration Suite, putting over 129,000 servers at risk. Researchers suspect involvement of #Sednit (aka Fancy Bear).

Read: hackread.com/zimbra-cve-2...

#CyberSecurity #Vulnerability #FancyBear #Zimbra
Zimbra CVE-2024-27443 XSS Flaw Hits 129K Servers, Sednit Suspected
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
May 24, 2025 at 2:46 PM
🇷🇺 🇺🇦 A notorious Russian military cyber espionage hacking group has been refining its malware to conduct long-term surveillance of targets in #Ukraine and beyond.

www.welivesecurity.com/en/eset-rese...

#Russia #cybersecurity
Sednit reloaded: Back in the trenches
ESET researchers document how the Sednit APT group has reemerged with a modern toolkit centered on two paired implants – BeardShell and Covenant.
www.welivesecurity.com
March 10, 2026 at 12:08 PM
Today, we released new @RecordedFuture research detailing BlueDelta’s expanded credential-harvesting activity observed between February and September 2025. #BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #ITG05 #PawnStorm #Sednit #Sofacy #TA422 (1/5) www.recordedfuture.com/research/gru...
GRU-Linked BlueDelta Evolves Credential Harvesting
Insikt Group reveals how GRU-linked BlueDelta evolved credential-harvesting campaigns targeting government, energy, and research organizations across Europe and Eurasia.
www.recordedfuture.com
January 7, 2026 at 3:39 PM
Detailed analysis of Sednit’s modern toolkits is available at www.welivesecurity.com/en/eset-rese... 5/5
Sednit reloaded: Back in the trenches
ESET researchers document how the Sednit APT group has reemerged with a modern toolkit centered on two paired implants – BeardShell and Covenant.
www.welivesecurity.com
March 10, 2026 at 2:28 PM
Sednit, aka APT28/Fancy Bear 🐻🇷🇺, is deploying two new potent hacking tools, Beardshell and Covenant, primarily targeting Ukrainian military personnel. My ESET colleagues analyze this GRU-homemade toolset in a new blogpost.
www.welivesecurity.com/en/eset-rese...
Sednit reloaded: Back in the trenches
ESET researchers document how the Sednit APT group has reemerged with a modern toolkit centered on two paired implants – BeardShell and Covenant.
www.welivesecurity.com
March 10, 2026 at 10:50 PM
Today, we released new @RecordedFuture research detailing BlueDelta’s sustained credential-harvesting campaign targeting UKR.NET users between June 2024 and April 2025. www.recordedfuture.com/research/blu...
#BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #PawnStorm #Sednit #Sofacy (1/5)
BlueDelta’s Persistent Campaign Against UKR.NET
Discover how Russia’s BlueDelta targets UKR.NET users with advanced credential-harvesting campaigns, evolving tradecraft, and multi-stage phishing techniques.
www.recordedfuture.com
December 17, 2025 at 3:46 PM
Українці знову стали ціллю російської групи кібершпигунів Sednit
cybercalm.org/ukrayintsi-z...
Українці знову стали ціллю російської групи кібершпигунів Sednit | CyberCalm
Компанія ESET попереджає про відновлення активності групи кіберзлочинців Sednit. Зокрема з квітня 2024 року вона використовує нові шкідливі інструменти
cybercalm.org
March 11, 2026 at 5:58 PM
Sednit also deployed BeardShell, an implant that executes PowerShell commands via a legitimate cloud service and uses a distinctive obfuscation technique also found in Xtunnel, Sednit’s network pivoting tool from the 2010s. 3/5
March 10, 2026 at 2:28 PM
Ukrainian officials confirm broad outlines of my reporting, but:

1️⃣ Some experts dispute or are agnostic about Ukrainians’ attribution to APT28/Pawnstorm/Sednit.

2️⃣ Some Ukrainian officials say there’s no evidence of theft, but data recovered by researchers included exfil.

bsky.app/profile/raph...
April 18, 2026 at 11:26 AM
Sednit reloaded: Back in the trenches
The resurgence of one of Russia’s most notorious APT groups
www.welivesecurity.com/en/eset-rese...
Sednit reloaded: Back in the trenches
ESET researchers document how the Sednit APT group has reemerged with a modern toolkit centered on two paired implants – BeardShell and Covenant.
www.welivesecurity.com
March 10, 2026 at 6:49 PM
Across 2025–2026, Sednit paired BeardShell with Covenant, the final block of its modern toolkit – a heavily reworked open-source implant built for long‑term espionage with a new protocol riding on another legitimate cloud provider. 4/5
March 10, 2026 at 2:28 PM
Фахівці з кібербезпеки попереджають про відновлення активності групи кіберзлочинців Sednit. Зокрема з квітня 2024 року вона використовує нові шкідливі інструменти BeardShell і Covenant для здійснення довгострокового шпигування за українськими військовими.
Українці знову стали ціллю російської групи кібершпигунів Sednit | CyberCalm
Компанія ESET попереджає про відновлення активності групи кіберзлочинців Sednit. Зокрема з квітня 2024 року вона використовує нові шкідливі інструменти
cybercalm.org
March 11, 2026 at 7:07 AM
#ESET team spent 2 years studying these vulnerabilities in webmail portals, finding zero-day flaws in Roundcube & MDaemon. Discover how Russia's Sednit, GreenCube, and Belarus Winter Vivern exploited XSS flaws in Roundcube, Zimbra,MDaemon & Horde to steal emails from high-value targets. 2/3
April 9, 2025 at 1:40 PM
"of hundreds of small office/home office (SOHO) routers that GRU Military Unit 26165, also known as APT 28, Sofacy Group, Forest Blizzard, Pawn Storm, Fancy Bear, and Sednit, used to conceal and otherwise enable a variety of crimes"
February 15, 2024 at 6:23 PM
This is the first post in a series about #Russia 's APT 28, aka Fancy Bear or Sednit, Sofacy, Forest Blizzard and many other names. There's been an exceptionally long trail of attacks and destruction this APT has been involved with, since early 2000s. #Ukraine #Georgia #NAFO #CyberSec
September 7, 2024 at 9:34 PM
Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit www.darkreading.com/cyber-risk/s...
Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit
After several years of using simple implants, the Russia-affiliated threat actor is back with two new sophisticated malware tools.
www.darkreading.com
March 14, 2026 at 3:42 AM
ESET Research: One of Russia’s most notorious groups, Sednit, resurges with spyware in Ukraine

ESET researchers recently traced the reactivation of Sednit through their modern toolkit, which is centered on two paired implants, BeardShell and Covenant, each using a different cloud provider for…
ESET Research: One of Russia’s most notorious groups, Sednit, resurges with spyware in Ukraine
ESET researchers recently traced the reactivation of Sednit through their modern toolkit, which is centered on two paired implants, BeardShell and Covenant, each using a different cloud provider for resilience. This dual‑implant approach enabled long‑term surveillance of Ukrainian military personnel and has been in use since April 2024. In 2016, the US Department of Justice linked the Sednit group to Unit 26165 of the GRU, a Russian Federation intelligence agency within the Main Intelligence Directorate of the Russian military.
itnerd.blog
March 10, 2026 at 4:26 PM
Hackers linked to Russia’s GRU have targeted defense companies in Bulgaria and Romania

odessa-journal.com/hackers-link...
Russian Hackers Target Bulgaria and Romania in Espionage Campaign Linked to Ukraine War - Oj
GRU-linked Sednit hackers attacked defense firms in Bulgaria and Romania to steal Ukraine-related data via vulnerabilities in webmail servers, ESET reveals.
odessa-journal.com
May 16, 2025 at 4:29 PM
Компанія ESET підготувала огляд активності APT-груп кіберзлочинців з жовтня 2024 до березня 2025 року. За цей період групи, пов’язані з росією, зокрема Sednit та Gamaredon, продовжували націлюватися на Україну та країни ЄС.
Поширені APT-загрози: російські кібератаки посилюються в Україні та ЄС | CyberCalm
Компанія ESET – лідер у галузі інформаційної безпеки – підготувала огляд активності APT-груп кіберзлочинців з жовтня 2024 до березня 2025 року. За цей період
cybercalm.org
May 19, 2025 at 2:08 PM
While #ClickFix was introduced by cybercriminals, it’s since been adopted by APT groups: Kimsuky, Lazarus; Callisto, Sednit; MuddyWater; APT36. NK-aligned actors used it to target developers, steal crypto and passwords from Metamask and #macOS Keychain. 5/7
July 18, 2025 at 12:06 PM